SOLUTIONS|UPDATED VERSION !!!|A+
What is the definition of single loss expectancy (SLE)? - ANSWER Financial loss from a
single event
Which of the following best describes residual risk? - ANSWER Original risk - mitigated
risk - transferred risk = residual risk.
Which entity usually performs quality assurance testing (QAT)? - ANSWER IT
department
All of the following are characteristics of "system hardening" EXCEPT: -
ANSWER Preserving default configurations
All of the following are often included as contract provisions when outsourcing a product or
process EXCEPT: - ANSWER Profit margin
Which term describes the time frame for the audit, geography, technology involved,
business process to be audited, and portion of the organization affected by the audit? -
ANSWER Scope
Who in the organization is legally responsible for overseeing the organization's activities? -
ANSWER Board of directors
Which term is the foundation for IS controls and is a statement of desired states or
outcomes from business operations? - ANSWER Control objective
1
,Why does an auditor follow up with management well after the completion of the audit? -
ANSWER To show interest and concern for the organization's health
All of the following should be considered in capacity planning EXCEPT: -
ANSWER Network protocols
Why are automatic controls preferred over manual controls? - ANSWER Automatic
controls function without human intervention.
Which level of project governance is responsible for approving the project, assigning IT
resources to the project, and approving the project schedule, among other responsibilities? -
ANSWER IT steering committee
Which of the following statements concerning viruses is true? - ANSWER Viruses are
fragments of code that attach themselves to .exe files (executable programs); a virus is
activated when the program it's attached to is run.
All of the following are centralized fire suppression systems EXCEPT: -
ANSWER Handheld fire extinguishers
How should physical media containing highly sensitive information be packaged and
transported? - ANSWER In a double-wrapped package; using a courier and requiring a
signature by the recipient
A security analyst needs to design a control to ensure that data that is input into a system
has been examined for completeness. What type of a control should be designed? -
ANSWER Input validation
Which of the following post-implementation items should be audited to ensure that systems
and infrastructures meet organizational requirements and are subject to internal controls? -
ANSWER The application supports the entire body of requirements established during
the project
2
, Which data recovery scheme involves the use of hot-swappable disk arrays in the equipment
chassis? - ANSWER RAID
An auditor has insufficient local storage to collect evidence during an audit. What is the
auditor's best course of action? - ANSWER Collect the evidence when the auditor has
sufficient storage available for the evidence.
What do you call the practice of setting an organization security policy and then taking steps
to ensure that the policy is followed? - ANSWER Security Governance
All of the following organization requirements are considered during the requirements
definition phase of the SDLC EXCEPT: - ANSWER Code design
All of the following should be considered when determining whether an individual requires
access to sensitive or classified information EXCEPT: - ANSWER Rank or position within
the organization
All of the following activities should be practiced by an organization in managing its software
licensing program EXCEPT: - ANSWER Allow employees to take home licensed
software for "personal use."
An auditor is evaluating a business process and has found that personnel perform tasks
consistently, but was told that there are no written procedure documents. What opinion
should the auditor write for this process? - ANSWER Minor exception: lack of
procedure document
When the root cause of a problem has been identified, which processes are enacted to make
temporary and permanent fixes? - ANSWER Change management and configuration
management
3